CVE-2024-47876

Severity CVSS v4.0:
HIGH
Type:
CWE-285 Improper Authorization
Publication date:
15/10/2024
Last modified:
30/10/2025

Description

Sakai is a Collaboration and Learning Environment. Starting in version 23.0 and prior to version 23.2, kernel users created with type roleview can log in as a normal user. This can result in illegal access being granted to the system. Version 23.3 fixes this vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sakailms:sakai:*:*:*:*:*:*:*:* 23.0 (including) 23.2 (excluding)